Berlin says Rhysida tried to extort the city after a breach of its administrative network, and the gang claims 1.44 million files and 30 bitcoin. Officials said the leak likely ran from Aug. 7 to Aug. 12, while the affected departments stayed connected until Aug. 14.
That gap matters because the longer a compromised department remains on the network, the more time an attacker has to pull data from adjacent systems. Berlin says investigators are still checking whether personal data or other non-public records were exposed, and Rhysida’s own leak page claims passwords, email addresses, and internal files from several administrative systems.
For local and state government networks, the exposure is not just the ransom demand: shared administrative environments can turn one intrusion into a multi-department data loss if disconnect comes late. The election environment was said to be separate and secure, but the reporting does not settle how much of the broader state network was already copied out before isolation.